Privacy Policy

Last Updated: June 8, 2026

This Privacy Policy describes how Flax ("we," "our," or "us") collects, uses, stores, and protects information when you use flaxsites.com, the Flax website builder, hosting platform, editor, dashboards, support tools, and related services (the "Service").

Flax is used by site owners to create and operate their own websites. This policy covers the data Flax processes for the Service. Site owners are responsible for telling their own visitors, customers, students, members, staff, and other end users how their website collects and uses personal information, including information handled through Flax-powered forms, checkout, booking, ticketing, course, staff, and point-of-sale features.

1. Information We Collect

1.1 Account Information

When you create or use a Flax account, we collect:

  • Email address and authentication identifiers
  • Name, profile information, and agency account settings
  • Invitations, roles, ownership transfers, and access history
  • Authentication credentials and sessions managed through Supabase Auth

1.2 Business and Site Content

When you build, import, edit, publish, or manage a website with Flax, we collect and store the content and configuration you provide, including:

  • Business name, type, country, locations, and contact details
  • Site text, pages, articles, services, products, events, courses, FAQs, reviews, menus, policies, and other content
  • Images, logos, favicons, documents, media files, and design settings
  • Forms, recipient settings, payment settings, booking settings, staff settings, and feature configuration
  • Published site URLs, deployment status, CDN configuration, and custom domain information
  • Local draft and editor data stored in your browser until you publish, sync, import, or clear it

1.3 Domains and Registrations

If you search for, connect, register, or renew domains through Flax, we may collect:

  • Domain names, registration status, renewal settings, and expiry dates
  • Registrant email and registrant contact details
  • Domain agreement receipts, consent records, IP address, user agent, provider order IDs, and related audit information

1.4 Integrations and Connected Services

If you connect third-party services, we collect the information needed to provide those integrations, such as:

  • Google account email, name, picture, connected property, Search Console, Google Business Profile, and analytics metadata
  • OAuth tokens for Google integrations, stored separately with restricted server-side access
  • Dodo Payments subscription and checkout metadata, Stripe account and connected payment metadata, payment method status, and product/payment configuration metadata
  • Google Docs import tokens or document content when you ask Flax to import from Google Docs

1.5 Payments and Billing

We use Dodo Payments for Flax subscriptions and checkout. We use Stripe for connected payments, domain checkout, and payment-related workflows where a site owner enables those features. These payment providers may collect payment card details, billing details, tax information, payment method details, and fraud prevention information. Flax does not store full payment card numbers. We store payment and billing metadata such as subscription IDs, checkout session IDs, payment status, pricing IDs, usage counters, billing trigger timestamps, and renewal records.

1.6 Visitor and Customer Data on User Sites

Flax provides infrastructure that site owners can use to collect or process information from their own visitors and customers. Depending on the features a site owner enables, this may include contact form submissions, messages, file uploads, orders, customer records, delivery details, bookings, attendees, ticket validation records, course access and progress, passes, memberships, staff accounts, scanner access, point-of-sale records, and related communications.

For these user-site features, Flax generally acts as a service provider or processor for the site owner. The site owner controls what they collect and must provide any privacy notices, consents, lawful bases, and retention terms required for their own site.

1.7 Support, Debug, and Communications Data

When you contact us, request support, submit debug packages, or receive service emails, we may collect your contact details, message content, reference IDs, site name, site ID, logs, model snapshots, attachments, and related troubleshooting information.

1.8 Technical and Usage Data

We collect technical and operational information such as:

  • IP address, user agent, device, browser, approximate location, and request metadata
  • Authentication, security, access, deployment, error, and performance logs
  • Feature usage, usage counters, idempotency keys, monthly report data, and billing-related usage totals
  • Cookie, local storage, and browser storage data needed for the Service to function

2. How We Use Your Information

We use information to:

  • Provide, maintain, secure, and improve the Service
  • Create, edit, host, publish, deploy, translate, and synchronize websites
  • Authenticate users and manage accounts, roles, invitations, ownership transfers, and agency/client access
  • Process subscriptions, billing, domain purchases, renewals, and usage-based limits
  • Operate optional features such as forms, checkout, bookings, tickets, products, courses, staff access, analytics, and AI-assisted editing
  • Connect and maintain third-party integrations you enable
  • Send transactional emails, support replies, invitations, alerts, reports, and administrative messages
  • Detect, prevent, and investigate spam, fraud, abuse, security incidents, and service misuse
  • Comply with legal, tax, accounting, domain registration, dispute, and regulatory obligations

3. Data Storage and Infrastructure

Flax uses a mix of managed cloud services, CDN-hosted edge scripts, browser storage, and per-site databases to provide the Service.

3.1 Supabase

Supabase stores account profiles, user sites, site metadata, deployment metadata, invitations, ownership transfers, domain records, domain compliance receipts, Google integration metadata and tokens, information requests, discount codes, usage counters, usage idempotency records, and monthly performance report snapshots. Supabase also provides authentication for Flax accounts.

3.2 Bunny.net CDN, Storage, Edge Scripts, and Databases

Published website files, images, assets, template content, support uploads, and CDN-delivered resources may be stored and delivered through Bunny.net. Flax also runs edge scripts on Bunny.net for publishing, forms, checkout, bookings, tickets, domains, integrations, support, and related APIs.

Some user-site features use per-site Bunny Database (libSQL/SQLite-compatible) databases. These databases may store end-user-site data such as customers, orders, order items, tickets, bookings, staff accounts, course access, lesson progress, passes, subscriptions, scanner access, and sync metadata. Site owners should describe those collections in their own privacy policies.

3.3 Browser Storage

The Flax editor may store drafts, uploaded local images, imported templates, article content, checklist preferences, course access state, UI preferences, and other working data in your browser using local storage, IndexedDB, or similar browser storage until it is published, synchronized, replaced, or cleared.

4. Data Sharing and Third Parties

We share information with service providers and integrations only as needed to provide, secure, support, or improve the Service, or when required by law.

4.1 Service Providers and Subprocessors

  • Supabase - database, authentication, storage-related APIs, and backend services
  • Bunny.net - CDN, storage, edge scripts, DNS/CDN configuration, and per-site databases
  • Dodo Payments - Flax subscriptions, checkout, payment processing, billing, tax handling, and fraud prevention
  • Stripe - connected payments, domain checkout, payment processing, billing, and fraud prevention
  • OpenSRS and domain providers - domain search, registration, renewal, registrant contacts, and required compliance records
  • Google - Google OAuth, Search Console, Business Profile, Analytics, Maps, Google Docs imports, and related integrations you enable
  • Resend and SMTP/email providers - transactional email, invitations, reports, contact form delivery, and support email
  • OpenAI or other AI providers - AI-assisted editing, generation, translation, or content-processing features when you choose to use them
  • ALTCHA, Cloudflare Turnstile, or anti-abuse providers - bot protection, abuse prevention, and security checks
  • Slack or internal notification tools - operational alerts and support workflows

4.2 Site Owners and Their End Users

If you are a visitor, customer, student, member, attendee, or staff user of a Flax-powered site, information you provide through that site is made available to the site owner and their authorized users. The site owner's own privacy policy applies to how they use that information.

4.3 Legal Requirements and Business Transfers

We may disclose information if required by law, legal process, or valid requests from public authorities; to protect rights, safety, and security; or as part of a merger, acquisition, financing, reorganization, or sale of assets.

5. International Data Transfers

Flax operates internationally. Your information may be transferred to, stored in, or processed in countries other than your country of residence, including countries where our infrastructure providers, subprocessors, users, or support staff operate.

Where required for transfers from the European Economic Area, United Kingdom, Switzerland, or other regions with transfer rules, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, data processing agreements, or other lawful transfer mechanisms.

6. Data Retention

We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business operations.

  • Account and profile data: retained while your account is active and for a reasonable period after deletion where needed for recovery, security, legal, or audit purposes
  • Site content and published assets: retained while your site is active or as needed for hosting, backups, recovery, and deletion workflows
  • Deleted sites: may be soft-deleted for recovery, audit, or abuse-prevention purposes before permanent removal
  • Domain and compliance records: retained as required for domain registration, registrar, audit, dispute, tax, and legal obligations
  • Billing and payment metadata: retained as required for billing, tax, accounting, fraud prevention, chargebacks, and legal compliance
  • OAuth tokens and integrations: retained while the integration is connected or as needed to complete disconnection, troubleshooting, or security processes
  • Usage idempotency records: designed to be cleaned up after approximately 90 days
  • Technical logs: generally retained for a limited period needed for security, debugging, reliability, and abuse prevention
  • User-site customer records: controlled by the site owner and retained according to the site owner's settings, feature use, legal obligations, and privacy policy

7. Your Rights

Depending on your location and your relationship with Flax or a Flax-powered site, you may have rights to access, correct, export, delete, restrict, object to, or withdraw consent for certain processing of your personal information.

7.1 Flax Account Users

  • Access, update, or correct your account and site information
  • Request deletion of your account or sites
  • Request a copy or export of information associated with your account
  • Disconnect integrations such as Google or Stripe where supported
  • Contact us about privacy, security, or data processing questions

7.2 Visitors and Customers of Flax-Powered Sites

If your request relates to a website operated by a Flax customer, please contact that site owner first. We can assist site owners in responding to valid requests where Flax processes data on their behalf.

7.3 Regional Rights

Residents of the EEA, UK, Switzerland, California, and other regions may have additional rights under applicable laws, including the right to lodge a complaint with a supervisory authority or to opt out of certain disclosures. We do not sell personal information as that term is commonly understood.

To exercise rights for data controlled by Flax, contact us at contact@flaxsites.com. We may need to verify your identity and account relationship before completing a request.

8. Data Security

We use technical and organizational measures designed to protect personal information, including:

  • Encryption in transit using TLS
  • Managed authentication through Supabase Auth
  • Row-level security and access controls for user-facing Supabase tables
  • Restricted server-side access for sensitive integration tokens and service credentials
  • Bot protection and abuse-prevention checks for public-facing workflows
  • Operational monitoring, debugging, and security review practices

No method of transmission or storage is completely secure. If you believe there is a security issue with Flax, please contact us at contact@flaxsites.com.

9. Cookies and Tracking

Flax uses cookies, local storage, IndexedDB, and similar technologies for authentication, session management, drafts, editor preferences, security, feature operation, and performance. We do not use third-party advertising cookies on the Flax platform.

Site owners may choose to enable Google Analytics, Google Maps, embedded content, payment tools, course access, checkout, booking, or other features on their published sites. Those features may set cookies or collect data according to the site owner's configuration and the applicable third-party provider's terms and privacy policy.

10. Children's Privacy

The Flax Service is not directed to children under 16. We do not knowingly collect personal information from children through Flax accounts. If you believe a child has provided personal information directly to Flax, contact us and we will take appropriate steps.

Flax-powered sites may be used by site owners for classes, events, courses, youth programs, or other offerings. Site owners are responsible for complying with laws that apply to children, students, parents, guardians, and participants on their own sites.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date. For material changes, we may also notify users by email or through the Service.

12. Contact Us

If you have questions, concerns, requests, or privacy-related notices for Flax, contact us at:

Email: contact@flaxsites.com

For requests about a Flax-powered site that you do not own, please contact the site owner directly first.